Cybersecurity FAQs
SHARE

Overview

Answers to frequently asked questions concerning the Cybersecurity Regulation are below. Capitalized terms used below have the meanings assigned to them in the definition section of Part 500. “Section” references are to sections of the Cybersecurity Regulation unless otherwise stated. 

The Department may revise or update the below information from time to time, as appropriate. These FAQs are explanatory and provided for informational purposes only. In the event of an inconsistency between and FAQ and the Cybersecurity Regulation, the Cybersecurity Regulation prevails.
 

Covered Entities

 

Governance

Risk Assessment

Third-Party Service Providers

Multi-Factor Authentication (MFA)

Notice of Cybersecurity Incidents

Annual Compliance Notifications

Exemptions